Legal and privacy

Privacy Policy

This policy explains what personal information we collect, why we use it, who we may share it with and the rights available to you.

Last reviewed: June 2026

Our commitment to your privacy

We are committed to protecting our members’ privacy. Information marked as mandatory for membership is required either to meet a legal obligation or to perform our contract with you. If you cannot provide it, we may not be able to open or operate an account. Where information is requested for another purpose, we will ask for your consent.

Information gathered from website visitors

We use analytics services to understand how visitors use our website. This may include standard internet log information and visitor behaviour patterns. Analytics information is intended to be reported anonymously.
  • Your IP address
  • Your web browser and operating system
  • The date, time and pages visited
  • Cookie and similar technology data

How we use personal information

We process personal information where required by law, to perform our contract with you, where we have a legitimate interest, or where you have given consent.
  • To confirm your identity and address
  • To prevent financial crime and complete internal or external audits
  • To maintain the register of members and operate your accounts
  • To consider applications and carry out credit and affordability checks
  • To obtain and provide credit references and recover debts
  • To analyse member needs and manage our organisation
  • To maintain our relationship with you, including agreed marketing and research

Member communications

As part of membership, we may send statements, new or amended terms and conditions, information about account changes and notices relating to our Annual General Meeting. Marketing communications are sent in accordance with your preferences and applicable law.

Sharing your information

We disclose personal information outside the credit union only where there is a lawful reason to do so.
  • Identity, anti-money laundering, politically exposed person and sanctions-checking providers
  • Credit reference agencies, fraud prevention agencies and debt recovery agents
  • Regulators, law enforcement and other authorities where required by law
  • Insurers and other providers delivering services or benefits connected with your account
  • Suppliers processing information on our behalf
  • Relevant parties in connection with a reorganisation or merger

International transfers

We do not directly send information outside the UK or European Economic Area as a routine activity. Some recipients or service providers may process information in other countries. Where this occurs, appropriate safeguards must be used. Information may also be transferred internationally where required by tax or other law.

Keeping and protecting information

We retain information for different periods depending on why it is held, including for a period after membership ends where required by law, regulation or legitimate business need. We do not keep information longer than necessary for the purpose for which it was collected.
Appropriate physical and technical safeguards are used. Data is encrypted when moved between locations and, where appropriate, while stored. Staff receive information security and data privacy awareness training, and relevant suppliers are expected to maintain equivalent standards.

Credit reference agencies

When you apply for credit, we may provide personal information to credit reference agencies and receive information about your financial history. This helps us assess creditworthiness and product suitability, verify identity, manage accounts, trace and recover debts and prevent crime.
We may continue to exchange information throughout the relationship, including information about settled accounts and debts not repaid on time. Records may be linked to a spouse, joint applicant or other financial associate and may be retained for up to six years after an agreement ends.

Information used in lending decisions

Credit reference information may include payment history, previous addresses, financial associations, name changes, fraud information and public records such as the electoral register, Companies House, insolvency records and County Court Judgments. We use it to verify information, lend responsibly, prevent financial crime and recover unpaid debts.

Automated assessment

We may use automated processing to assist credit decisions. Where possible, automated recommendations are reviewed manually, and you may request a manual review if you are unhappy with a decision.
NestEgg Ltd processes some data on our behalf and provides recommendations to our loan officers. Application checks may leave several search footprints relating to identity, credit and affordability data. Some may appear in the name of NestEgg Ltd and others in the name of the credit union.

Fraud prevention

We and fraud prevention agencies process and share information to prevent fraud and money laundering. This may include identity, contact, financial and employment information, device identifiers and other information we are legally required or legitimately entitled to share.
Law enforcement may access this information where necessary. Fraud prevention agencies may retain information for different periods and, where a fraud or money-laundering risk is identified, for up to six years. A risk finding may result in services being refused or withdrawn.

Your data protection rights

  • To request access to personal information held about you
  • To ask for inaccurate information to be corrected
  • To request erasure where the law allows
  • To restrict processing in certain circumstances
  • To object to processing based on legitimate interests or for direct marketing
  • To request a manual review of an automated decision
  • To withdraw consent at any time, without affecting earlier lawful processing

Complaints and the Information Commissioner

If you are dissatisfied with how we manage your privacy or data, you can use our complaints procedure.
You also have the right to complain to the Information Commissioner’s Office at ico.org.uk, by telephone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, SK9 5AF.

Need help with this policy?

Contact our team if you need this information in another format or would like us to explain any part of it.

Contact Us